You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 30, 2026

Key Takeaways from Thailand’s Data Privacy Day 2026

Thailand’s Data Privacy Day 2026, hosted by the Office of the Personal Data Protection Committee (PDPC), underscored the country’s commitment to strengthening personal data protection, advancing regulatory maturity, and preparing organizations for the next phase of PDPA enforcement. The event marked a clear shift from policy-level compliance toward “Privacy in Action,” signaling that operational readiness and real-world implementation are now priorities.

The Office of the PDPC also emphasized that data protection is now a national economic enabler that supports digital trust, competitiveness, and sustainable growth, not just a compliance obligation.

The following insights summarize the key takeaways from the Data Privacy Day 2026 event.

PDPA in Real Life: What Happens to Your Data Today

The Office of the PDPC provided concrete data on enforcement trends and real-world compliance issues facing organizations across Thailand.

Complaints and trends. The Office of the PDPC’s Personal Data Protection Act (PDPA) Center recorded 2,672 PDPA-related complaints as of January 2026, with the highest volumes involving failure to comply with the data minimization principle, collection without lawful basis, and use and disclosure without lawful basis.

Administrative penalties. Several administrative penalties have been imposed on data controllers and data processors across various sectors, including government, healthcare, retail, SMEs and e-commerce, ranging from tens of thousands to several million baht. Most violations stemmed from weak security measures, failure to notify data breaches within the required timeline, absence of a data protection officer (DPO) when required, and noncompliance with governance requirements such as the Record of Processing Activities (ROPA) and data processing agreements with data processors.

Case studies. The Office of the PDPC highlighted specific examples of violations:

  • Hospitals misused personal data for purposes beyond their intended scope (e.g., using personal data collected for providing medical services to send birthday cards)
  • Vendors compromised systems due to inadequate password protocols and the absence of firewalls, resulting in unauthorized access

AI and Privacy: Regulatory Expectations in the Emerging Landscape

Thailand is moving toward a clearer regulatory framework for AI, with the AI Act currently in draft form. While the PDPA does not regulate AI itself, it governs personal data used within AI systems, meaning organizations, not the AI, remain fully accountable for any misuse or unlawful processing of personal data.

Key expectations highlighted for businesses include:

  • The use of AI is allowed, but accountability remains fundamental. Organizations must take full responsibility for how personal data is processed through AI systems.
  • Strong resource and access governance is necessary. Organizations must prevent uncontrolled AI usage and avoid over-sharing of data through proper data classification to restrict AI access to relevant datasets.
  • AI deployment may trigger obligations under other laws. While there is currently no specific law regulating the use of AI, AI deployment may trigger obligations under civil and commercial law, road traffic laws in relation to autonomous systems, and other regulations, reinforcing the need for comprehensive risk assessment.
  • Alignment with forthcoming guidelines. The Office of the PDPC is currently developing practical guidelines on personal data protection in the use and development of AI technologies. Organizations should align AI use with these forthcoming guidelines aimed at supporting safe innovation while adhering to PDPA requirements.

International Cooperation and Cross-Border Transfers

Efforts continue to advance Thailand’s participation in the Global Cross-Border Privacy Rules (CBPR) and strengthen alignment with regional data-protection frameworks. Organizations operating across borders should expect tighter scrutiny of cross-border transfers, including more rigorous requirements for risk assessments and transfer impact analyses to ensure compliance in multi-jurisdictional environments.

Data Breach Incident Monitoring

The PDPC Eagle Eye, a division within the Office of the PDPC, has launched advanced tools such as the PDPC Eagle Eye Crawler, which enables continuous URL access and facilitates 24-hour monitoring of data breach incidents. Additionally, the PDPC Eagle Eye shared details about their plan to send inspection letters to organizations for advisory reasons.

Privacy Maturity Model and Privacy Index

The Office of the PDPC introduced new tools to help organizations assess and improve their data protection practices.

The Privacy Maturity Model assesses an organization’s readiness for personal data protection. The Privacy Index measures data protection levels using both privacy data (such as survey results and Privacy Maturity Model scores) and secondary data (like public information), giving organizations an overview of their privacy risk management capabilities.

Information derived from the Privacy Maturity Model and Privacy Index can then be used toward obtaining the Personal Data Protection Certification Mark, an upcoming certification program to recognize compliant organizations.

Outlook for 2026

Based on the Office of the PDPC’s roadmap and expert discussions during the Data Privacy Day event, organizations should expect several key developments in the coming year:

  • Data privacy must go beyond policy and legal compliance to practical implementation in all systems and operations.
  • Heightened enforcement, driven by expanded automated surveillance capabilities such as the PDPC Eagle Eye Crawler and the rollout of inspection letters for advisory purposes.
  • Stronger national PDPA infrastructure, with continued development of PDPA Centers and Trustmark certification.
  • Closer alignment with international privacy standards, supporting Thailand’s role in cross-border digital trade and strengthened mechanisms to support trusted cross-border data flows.
  • Increased regulatory attention on AI governance, with forthcoming guidance to ensure AI use complies with data-protection principles and standards.
  • A nationwide push toward a “new data-ethics culture” emphasizing legal compliance, incident prevention, organizational cooperation, and the use of technology to strengthen national and public trust, anchored in the national goal of improving data security, attracting investments, and enhancing quality of life.

Organizations should treat 2026 as a critical year for operationalizing privacy compliance, building robust governance frameworks, and preparing for more active regulatory oversight. The shift from policy to practice means that demonstrable implementation, not just documentation, will be the standard by which compliance is measured.

RELATED INSIGHTS​ 

November 25, 2024
Thailand has released the set of principles that will form the official draft Platform Economy Act (PEA) for a public hearing period that runs until December 15, 2024. The PEA is likely to be positioned as a general or overarching law for digital intermediary services and digital platform service businesses. In January 2024, an early, unofficial version of the proposed law had been circulated among a limited group of operators in certain industries to get comments for the working group charged with the PEA’s development. Now, however, the proposed principles that will underpin the official draft PEA have been released publicly to gather comments, feedback, and suggestions from any interested stakeholders. The principles of the draft PEA cover two main areas: user protection and fair competition. The key details in these two areas are outlined below. User Protection The main regulator supervising the law’s user protection elements will be the Electronic Transactions Development Agency (ETDA). The draft PEA is expected to impose user protection obligations on service providers based on their nature, size, and risk level. The principles set out a three-tiered classification system for service providers that will be covered under the draft PEA, as detailed below, ordered from fewest obligations to most: Intermediary Service Provider: This describes a service provider acting as an intermediary between a sender and recipient of information on a computer network, the internet, or a telecommunications network. Service providers likely to fall under this category include cloud service providers and web hosting providers. Intermediary service providers may be further categorized into the following subtypes: Mere conduit service providers; Caching service providers; Hosting service providers; and Other service providers as prescribed in ministerial regulations. Online Platform: This refers to an intermediary service provider offering data storage services that connect various types of users to
November 15, 2024
Vietnam’s new Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”), which will come into effect on December 25, 2024, replacing Decree No. 72/2013/ND-CP (“Decree 72”), introduces several changes to the regime for domain name dispute resolution. The new decree aims to clarify the legal framework and address some longstanding inconsistencies between Vietnam’s laws on intellectual property and information technology. The main changes related to domain name dispute resolution under Decree 147 are summarized below. Removal of Prescriptive Actions Decree 147 no longer lists specific actions for resolving domain name disputes. Decree 72 had outlined three methods: negotiation/mediation, arbitration, and court. However, IP practitioners had long criticized this approach, arguing it conflicted with the IP Law, which additionally allows administrative action. By omitting these methods, the new decree implies an acceptance of administrative action as provided in the IP Law. However, Decree 147 remains silent on establishing a dispute resolution forum aligned with the CPTPP’s requirement for a UDRP-like model. Currently, Vietnam’s available forums do not fully conform to the UDRP framework. An anticipated circular may provide further guidance on this aspect. Deactivation of Domain Names Decree 72 does not have any provision on the deactivation of a domain name. However, Decree 147 has stipulated some situations where domain names will be deactivated, such as when there is a request from an authority, or when it is discovered that incorrect information was used for registration. Clearer Criteria for Dispute Resolution Article 16 of Decree 147 sets out three clear criteria that must be met for domain name dispute resolution to proceed: (i) confusing similarity with the plaintiff’s trademark, trade name, or personal name; (ii) the defendant’s lack of legitimate rights or interests in the domain name; and (iii) bad faith. Previously,
November 15, 2024
On November 9, 2024, the government of Vietnam promulgated Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”). This decree supersedes the previous Decree No. 72/2013/ND-CP dated July 15, 2013, on the same topic (“Decree 72”) and its amending regulations, and will take effect on December 25, 2024. Spanning over 200 pages, with an appendix of 62 forms, Decree 147 addresses a wide range of key internet and online topics, including internet services; domain names; cross-border information provision; social network services; aggregated information websites; online game services; app store services; information content services on mobile telecom networks; responsibilities of telecom, internet, web hosting, data center, and telecom application service providers; and measures to handle illegal content. This decree is expected to have a significant impact on both onshore and offshore service providers in the respective fields, and will potentially tighten the regulatory landscape for internet services and online information provision in Vietnam. Some highlights from the new Decree 147 compared to its predecessor are detailed below. Cross-Border Information Provision Offshore service providers, including offshore social network service providers and offshore app store service providers, who provide services on a cross-border basis and either lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months must adhere to stricter requirements than other providers. Notable obligations of these regulated cross-border providers include: Notifying the Authority of Broadcasting and Electronic Information (ABEI) of their contact information. Monitoring and removing illegal content. Storing and managing user data as required. Authenticating social network user accounts using Vietnamese mobile number or ID number. Reporting to the ABEI annually as well as on an ad hoc Handling user complaints. Only cross-border providers who have notified the
November 13, 2024
Thailand’s Electronic Transactions Committee has publicized a new draft notification detailing additional duties for specific marketplace digital platform service operators under Section 18(2) of the Royal Decree on Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022). The draft notification, which is open for public comments until November 30, 2024, aims to provide enhanced protection for users of “specific marketplace platforms” (defined below). Some key points of the draft notification are detailed below. Scope The draft notification applies to “marketplace digital platform services,” which refers to digital platform services that serve as an intermediary for buying or exchanging goods and provide services to facilitate sale transactions, such as providing communication systems (e.g., chat features), shopping carts, delivery arrangements, and supplemental payment processing facilitation. “Specific marketplace platforms” refers to Section 18(2) of the Royal Decree on Digital Platform Services, which covers digital platform services that pose risks to financial and commercial security, the reliability and credibility of data messaging systems, or potential harm to the public, and that have a high level of potential impact based on the criteria for assessing the impact of digital platform service operations. Key Obligations Registration. The draft notification requires the marketplace operators mentioned above to be registered as legal entities in Thailand. Terms and conditions. The draft notification details additional obligations relating to marketplace operators’ terms and conditions: In addition to existing obligations prescribed in the Royal Decree and the relevant subordinate laws, the draft notification emphasizes that the terms and conditions must be in Thai, clear, accessible, and understandable, and may include graphical elements to aid explanation. The terms and conditions must prescribe conditions relating to the sale of products subject to specific standards, such as those restricted under the Food Act, the Drugs Act, and the Industrial Product